Welcome | Sign In
CRMBuyer.com
Product News

Oracle Rolls Out 51 Security Patches

Print Version
E-Mail Article
Reprints
Oracle Rolls Out 51 Security Patches

Oracle released a new Critical Patch Update addressing 51 security flaws across a variety of its products. Twenty-six of the patches are for Oracle Database products, many of them addressing vulnerabilities to remote intrusion without a user name or password. The update also includes non-security fixes that are required by the security patches.


eMarketer Whitepaper: Optimizing the E-Commerce Experience
From the Web to the Contact Center, are you prepared to proactively engage and keep your savvy customers? Read how e-commerce leaders are optimizing their sites with ratings, reviews, live help, Web analytics, mobile and more.

Oracle (Nasdaq: ORCL) on Tuesday released a new Critical Patch Update addressing 51 security flaws across a variety of its products. The release was Oracle's ninth such quarterly update, and was the first to be preannounced. The release was initially announced last Thursday.

Included among the patches are security fixes for Oracle Database Server, Oracle Applications Server, Oracle Collaboration Suite, Oracle E-Business Suite, Oracle Enterprise Manager and Oracle PeopleSoft Enterprise Applications.

Twenty-six of the patches are for Oracle Database products, many of them addressing vulnerabilities to remote intrusion without a user name or password. The update also includes non-security fixes that are required by the security patches. The company recommends that customers apply all patches promptly.

52 Minus 1

Although the preannouncement had indicated that 52 patches would be released, one was withheld at the last minute after a technical problem was discovered, according to a blog written by Eric Maurice, manager for security in Oracle's Global Technology Business Unit.

"Per our policy, which is intended to ensure that all customers have an equal security posture, we removed the fix from the January CPU," Maurice said. The missing patch will be released in the next Critical Patch Update, due in April, he added. The last Critical Patch Update, released in October, included 101 fixes.

Starting last October, Redwood Shores, Calif.-based Oracle expanded its Critical Patch Update documentation to include executive summaries and common vulnerability scoring system (CVSS) scores to reflect the severity of the security flaws being addressed. It also began explicitly identifying vulnerabilities that could be remotely exploitable without authentication via user name and password.

By preannouncing the patches coming in forthcoming updates and providing expanded information about what they will entail, the company hopes to help customers be better prepared and keep their data safe.

Listening to the Customers

"Oracle introduced these changes as the result of feedback we received from many of our customers," Maurice explained. "We hope that these changes will help our customers assess the criticality of the vulnerabilities resolved with each [update] and help them obtain patching decisions from their senior management more quickly.

"Ultimately, we feel these changes should result in further strengthening the security posture of our clients by providing a standard approach to vulnerability scoring and a means for better internal communication."

The improved communication with customers seems to be a strategy Oracle has embraced following its acquisition of PeopleSoft, Siebel and others, and is bound to improve customer Increase Customer Sales with Email Marketing -- Free Trial from VerticalResponse relations, noted Rebecca Wettemann, vice president of research for Nucleus Research.

"I think it's a great move on Oracle's part," Wettemann said. "The more they can help customers plan for the future, the happier and more loyal those customers will be."


Print Version E-Mail Article Reprints More by Katherine Noyes


Related News Alerts

Oracle Activate Alert | Search Archives

More by Katherine Noyes

FOSS and the Google Question
November 19, 2009
How FOSSy is Google, really? "I find it kinda funny that folks tout that Google uses Linux when the most useful tool they have developed -- the Google FS -- they keep internally and therefore don't have to share the code!" observed Slashdot blogger hairyfeet. "So how exactly is Google different from MSFT and Apple, who have both in the past locked up free code for themselves?"
Can T-Mobile Get Its Groove Back?
November 18, 2009
T-Mobile may have a hard time pulling itself out of a swamp of customer discontent if it doesn't reverse course soon. The wireless carrier has been having some bad luck that has only been compounded by some poor decisions. "It takes a long time and much effort to build customer confidence, but a very short time to lose it," remarked telecom analyst Jeff Kagan.
Microsoft Goof - One Small Snag in a Code-Licensing Quagmire
November 17, 2009
Microsoft will open source the code to a Windows 7 tool in order to rectify the erroneous inclusion of code licensed under the GPL. Redmond's response to the problem "does indicate a growing maturity with respect to free and open source licenses," said RedMonk analyst Stephen O'Grady.
Don't miss a story -- sign up for our FREE e-mail newsletters and view the latest headlines at a glance.
Tech News Flash [ View Sample ]
E-Commerce Minute [ View Sample ]
ECT News Network Weekly Newsletter [ View Sample ]
Shortcuts
ECT News Network Information
Reader Services
Corporate
ECT News Network